CVE-2025-59968

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/10/2025
Last modified:
23/01/2026

Description

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface. <br /> <br /> <br /> <br /> <br /> Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls.<br /> <br /> <br /> <br /> This issue affects Junos Space Security Director <br /> * all versions prior to 24.1R3 Patch V4<br /> <br /> <br /> This issue does not affect managed cSRX Series devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juniper:space_security_director:*:*:*:*:*:*:*:* 24.1 (excluding)
cpe:2.3:a:juniper:space_security_director:24.1:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r3:*:*:*:*:*:*
cpe:2.3:a:juniper:vsrx:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4120:-:*:*:*:*:*:*:*